Opens in a new tab

MGM Resorts Cyber Attack Disrupts Operations

MGM Resorts shuts down systems after cyber attack

The MGM Resorts cyber attack has forced the hospitality and entertainment company to take some computer systems offline. The containment measure has disrupted operations, although the full scope of the incident has not yet been disclosed.

The incident was reported on 23 September 2026. At the time of publication, available reporting did not identify the attackers, the initial route into MGM Resorts’ environment, or whether customer or employee information had been accessed.

What happened in the MGM Resorts cyber attack

MGM Resorts shut down some of its computer systems after identifying a cyber attack affecting its operations. Taking systems offline is a common containment decision during an active incident because it can restrict an attacker’s access and give responders time to investigate affected infrastructure.

The shutdown itself can also cause significant disruption. Hospitality businesses depend on connected systems to support customer service, internal communications, payments, reservations, property management and other daily processes. The original report confirmed operational disruption but did not specify which individual services were unavailable.

It is therefore not currently possible to confirm whether the MGM Resorts cyber attack affected particular hotels, casinos, offices or digital services. No verified list of affected properties or geographical locations was included in the available reporting.

Systems and products affected

MGM Resorts has described taking some computer systems offline, but the report did not name the affected platforms, software products, hardware or cloud services. It also did not provide product versions, technical indicators of compromise or details of any exploited vulnerability.

This distinction is important. An operational shutdown does not necessarily mean that every unavailable system was directly compromised. Organisations may disconnect healthy systems as a precaution because they share networks, identity services or data flows with infrastructure under investigation.

There is also no confirmed information about whether the shutdown was initiated manually by MGM Resorts’ security team or triggered through an automated protective control. The available account supports only the conclusion that selected systems were taken offline following the cyber attack.

MGM Resorts cyber attack timeline and current status

The limited confirmed timeline begins with MGM Resorts identifying a cyber attack and responding by shutting down some computer systems. The incident and resulting disruption were reported on 23 September 2026.

  • MGM Resorts detected or became aware of a cyber attack affecting its technology environment.
  • The company took some computer systems offline as a containment measure.
  • The shutdown caused disruption to normal business operations.
  • The incident was publicly reported on 23 September 2026.
  • No recovery timetable, technical cause or complete impact assessment was included in the report.

No earlier detection date was provided, so it is unclear how long the attackers may have had access before systems were disconnected. The report also did not establish when all affected services would return or whether recovery was being completed in stages.

Attack method remains unconfirmed

There is currently no verified explanation of how the MGM Resorts cyber attack began. The available source does not attribute it to phishing, stolen credentials, social engineering, malware, a software vulnerability or a compromised supplier.

No ransomware group or other threat actor has been publicly linked to the event in the supplied reporting. There is also no confirmed ransom demand, extortion claim or evidence that stolen information has been published.

Without technical findings or a company statement explaining the entry point, attributing the incident to a particular technique would be speculative. Further investigation would normally involve reviewing identity activity, endpoint records, network traffic, administrator actions and access to sensitive repositories.

Who may be affected

The clearest confirmed impact is on MGM Resorts and its operations. Employees may have needed to use alternative procedures while systems were unavailable, while customers could experience delays where services depend on disconnected technology. However, the source did not define the exact customer impact.

It is not known whether personal, financial or corporate information was viewed, copied or altered. There was no confirmed data breach notice in the report, and the absence of such a notice at this stage should not be interpreted as proof that no information was exposed.

Incident investigations often take time because responders must distinguish malicious activity from normal system use. MGM Resorts would also need to determine which accounts, devices and data sources were involved before describing the affected population with confidence.

What remains unknown about the incident

Several central questions about the MGM Resorts cyber attack remain unanswered. These gaps limit the ability of customers, suppliers and security teams to assess whether they face any direct exposure.

  • The identity and motive of the attacker have not been confirmed.
  • The initial access route has not been disclosed.
  • No affected software products or versions have been named.
  • The number and location of disrupted properties remain unclear.
  • No confirmed volume or category of exposed data has been reported.
  • The company has not provided a complete recovery schedule in the available report.

The current exploitation status is similarly unclear. Reporting confirms a cyber attack against MGM Resorts, but it does not establish whether the activity is ongoing, fully contained or connected to a broader campaign targeting other hospitality companies.

Organisations should avoid treating unsupported online claims as established facts. Reliable updates would be expected to come from MGM Resorts, relevant regulators, law enforcement agencies or technical investigators with direct knowledge of the incident.

Why the MGM Resorts cyber attack matters

The event demonstrates how containment decisions can create immediate business consequences even before an investigation confirms data loss. Disconnecting systems may be necessary to prevent further attacker movement, but it can also interrupt customer-facing and administrative processes.

Hospitality environments can be especially sensitive to technology outages because numerous services operate continuously and share identity, payment and operational dependencies. The MGM Resorts cyber attack shows why incident response plans must account for both technical containment and the continuation of essential services.

What organisations should do now

There is no disclosed vulnerability or named product for organisations to patch in direct response to this incident. Security teams should instead monitor verified updates for technical indicators, affected suppliers or attack methods that may create a specific exposure.

  • Confirm that teams can isolate selected systems without unnecessarily disabling the whole environment.
  • Review offline procedures for critical customer, payment and operational services.
  • Protect privileged and remote access with strong authentication and active monitoring.
  • Ensure incident records are retained so investigators can reconstruct suspicious activity.
  • Prepare clear internal and external communications for extended technology disruption.

These actions should be tested against the organisation’s actual system dependencies rather than treated as a generic checklist. The central lesson from this event is that containment, investigation and business continuity may all need to operate at the same time.

Originally reported by Unknown.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call